A risk assessment is where your whole AML/CTF program starts. It is the documented exercise of working out how money laundering and terrorism financing could touch your business, and how exposed each part of it is. AUSTRAC expects you to look at 4 areas: your customers, the designated services you provide, how you deliver them, and the jurisdictions you deal with. Get this right and the rest of the program almost writes itself, because the policies just respond to what you found.
The trap is treating it as a form. A template with blank fields invites you to tick boxes and move on. That is not what this is. A risk assessment is a way of scoring: for each factor you ask how easily a criminal could exploit it in your specific business, you rate it, and you write down why. AUSTRAC is clear that the reasoning has to be documented, not just the final rating. A rating with no rationale behind it does not hold up.
Figure 1. You score 4 factors for how easily each could be exploited, reach a rating, and that rating sets the CDD you run.
The 4 risk factors to cover
These 4 are the spine of any AUSTRAC risk assessment. Miss one and you have not met the obligation to identify the risks your business may reasonably face.
Your customers
Who are they, really. An Australian resident buying their own home is one thing. A discretionary trust, a company with layered ownership, or a politically exposed person is another. Complexity and opacity raise risk because they make it harder to see who actually benefits. This is where most of the real work sits.
Your designated services
Each designated service you provide carries its own exposure. High-value transactions, and services that help a customer hold structures that disguise the source of their funds or wealth, sit higher. List every service you offer and rate each one rather than averaging across the business.
Your delivery channels
How the service reaches the customer matters. Face-to-face dealing is easier to scrutinise than fully remote onboarding. Instructions arriving through a third party or intermediary, with little direct contact, are a recognised channel risk because they can hide who you are really dealing with.
Your jurisdictions
List the countries your business touches when providing services: where customers are based, where their funds come from, where structures sit. Links to higher-risk jurisdictions push risk up. You also assess proliferation financing risk as part of the same exercise, even if your answer is that you have no exposure to it.
The 2 sectors, side by side
The 4 factors are the same for everyone. What fills them in is not. Here is how they tend to look across a real estate agency and a law practice.
Risk factor | In a real estate agency | In a law practice |
Customers | Overseas buyers, trust and company purchasers, buyers with complex or opaque ownership | Clients using trusts and companies, parties you never meet in person, PEPs |
Designated services | Brokering high-value purchases and sales, buyer’s agent work | Conveyancing, handling client money, helping form companies and trusts |
Delivery channels | In-person inspections vs fully remote deals, offers made through intermediaries | Instructions through a third party, online onboarding, acting for an absent client |
Jurisdictions | Buyers or deposit funds from higher-risk countries, cross-border money | Clients or funds connected to higher-risk jurisdictions, offshore structures |
Turning factors into a rating
Once you have identified the risks in each category, you assess them. AUSTRAC frames this as judging the scale of vulnerability: how easily each risk could be exploited to facilitate money laundering or terrorism financing. Score the inherent risk first, meaning the risk before your controls, then consider how much your controls bring it down to a residual risk you can live with. That produces a customer risk rating, usually low, medium or high. A low-risk customer is an Australian resident seeking a low-risk service with no red flags. A high-risk customer has things like an unusually complex control structure, or is seeking a service with no clear economic or lawful purpose. The rating is not the end point. It sets the depth of customer due diligence you run, with enhanced due diligence triggered at the high end.
A worked example
Take an overseas buyer purchasing a $2.5 million apartment through a company you have not dealt with before, with the deposit wired from an offshore account. Score the factors. The customer is a foreign-controlled company, so customer risk is high. The service is a high-value property purchase, so service risk is high. The funds cross a border from a jurisdiction you need to check, so jurisdiction risk is at least medium. Nothing here is low. The overall rating lands high, which means enhanced due diligence: you establish the source of the funds and the source of the buyer’s wealth, and you work out who actually controls the company before you go further. Compare that to a local resident buying a home they will live in, paying through an Australian bank, which scores low across the board and gets standard CDD. Same 4 factors, very different answers, and the rating tells you exactly how hard to look.
The regulatory detail
What the Act requires
Under the reformed Act your risk assessment must be documented and kept up to date, and it must cover money laundering, terrorism financing and proliferation financing. It has to be tailored to the nature, size and complexity of your business. It is 1 of the 2 components of your AML/CTF program, sitting alongside your policies, with the provisions at sections 26B to 26L. If you are a small, low-complexity firm, the AUSTRAC starter kit gives you a risk assessment template, but you still have to populate it with real data about your own customers, services and exposure.
How it drives the rest of the program
The risk assessment is not a standalone document you file and forget. The ratings it produces flow straight into your policies and your CDD workflow: who needs more scrutiny, when enhanced due diligence kicks in, what you collect and verify. Tooling helps here by tying each customer’s rating to the checks and the evidence trail that follow from it. If you are building from scratch, the risk assessment is step 1 of a 90-day plan to get the whole program in place.
When to review it
Treat it as a living document. You revisit it on a set cadence and whenever something material changes: a new designated service, a new client demographic, a new delivery method, an acquisition, or fresh AUSTRAC guidance. A risk assessment that describes last year’s business is not doing its job.
Common questions
What is an ML/TF risk assessment?
It is the documented exercise of identifying and rating how money laundering, terrorism financing and proliferation financing could affect your business, across your customers, services, channels and jurisdictions. It is the foundation your AML/CTF policies are built on.
What are the main risk factors?
Customers, designated services, delivery channels and jurisdictions, plus proliferation financing risk assessed in the same exercise. AUSTRAC expects all of them to be considered and the reasoning documented.
Do I need a separate risk assessment for each service?
You assess each designated service rather than averaging across the business, but they sit within one risk assessment. A firm offering both legal and conveyancing services may need to assess each line on its own terms.
Who can do the risk assessment?
Your compliance officer usually owns it, drawing on people who know the business. It does not have to be outsourced, but it does have to be informed and clearly documented. AUSTRAC’s risk products and sector indicators are a useful starting point.
How does the rating affect customer due diligence?
Directly. A low rating means standard CDD. A high rating triggers enhanced CDD, including closer checks on the source of funds and wealth. The rating is the link between the risk assessment and what you actually do at onboarding.
Sources
AUSTRAC, Step 2: Identify and assess your risks (risk assessment) (Reform)
AUSTRAC, Assigning customer risk ratings (Reform)
Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
